Start here
The safe first move
Treat .eslintrc.js and its cousins as a repo-fit boundary. The honest move is to detect them, report them, and leave them untouched.
Stop before automation when: Any JS config that computes env, plugins, or rules. Module imports inside the config file.
Target shape
// manual review required
// keep logic-bearing config out of the deterministic path